CVE-2026-102489 – Zammad 7.0 and later are not affected

We first received a report about this issue in August 2026 and analyzed it at that time. Exploitation is only possible on Zammad 6.5 and earlier versions due to the runtime environment used by these versions. These releases have been out of support for some time and no longer receive security updates.

Zammad 7.0 and later are not affected in practice. DIVD’s own case page also states that, the vulnerability cannot be exploited under the runtime environment used by these versions.

As an additional hardening measure, we have changed the affected code. This change is included in Zammad 7.2.0.

CVE-2026-102490 – local privilege escalation

We have received the technical details of this vulnerability from DIVD and are analyzing the issue as a high-priority item.

Based on our current assessment, this is a local privilege escalation vulnerability that cannot be exploited remotely on its own. An attacker would need access to the underlying server beforehand to exploit the vulnerability and escalate privileges.

This issue is related to a confirmed vulnerability in packager.io, and our team is working on a solution.

We recommend the following to administrators:

  • If you are still using Zammad 6.5 or an older version, update immediately. These versions no longer receive security updates.
  • Restrict access to the underlying Zammad server to trusted administrators only.

About the disclosure process

We support coordinated vulnerability disclosure. In this case, information about CVE-2026-102490 was made public before we received the technical details necessary to reproduce and evaluate the issue. Since then, we have received these details from DIVD and are addressing the issue as a high priority.

Contact for security researchers

Security researchers can report vulnerabilities at any time to security@zammad.com. Our public PGP key is available for encrypted messages. We welcome coordinated disclosure and collaboration with security researchers.